cbcvebase.
CVE-2024-35845
published 2024-05-17

CVE-2024-35845: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a…

PriorityP342critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.17%
64.2th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= a9248de42464e546b624e3fc6a8b04b991af3591 < fabe2db7de32a881e437ee69db32e0de785a6209fabe2db7de32a881e437ee69db32e0de785a6209
linuxlinux>= a9248de42464e546b624e3fc6a8b04b991af3591 < 96aa40761673da045a7774f874487cdb50c6a2f796aa40761673da045a7774f874487cdb50c6a2f7
linuxlinux>= a9248de42464e546b624e3fc6a8b04b991af3591 < c855a1a5b7e3de57e6b1b29563113d5e3bfdb89ac855a1a5b7e3de57e6b1b29563113d5e3bfdb89a
linuxlinux>= a9248de42464e546b624e3fc6a8b04b991af3591 < 783d413f332a3ebec916664b366c28f58147f82c783d413f332a3ebec916664b366c28f58147f82c
linuxlinux>= a9248de42464e546b624e3fc6a8b04b991af3591 < fec14d1cdd92f340b9ba2bd220abf96f9609f2a9fec14d1cdd92f340b9ba2bd220abf96f9609f2a9
linuxlinux>= a9248de42464e546b624e3fc6a8b04b991af3591 < 71d4186d470e9cda7cd1a0921b4afda737c6f64171d4186d470e9cda7cd1a0921b4afda737c6f641
linuxlinux>= a9248de42464e546b624e3fc6a8b04b991af3591 < ea1d166fae14e05d49ffb0ea9fcd4658f8d3dceaea1d166fae14e05d49ffb0ea9fcd4658f8d3dcea
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.5 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.